# Multiple logstash config files

**URL:** <https://discuss.elastic.co/t/multiple-logstash-config-files/130471>\
**Category:** Logstash\
**Created:** [May 3, 2018, 2:12pm UTC](https://discuss.elastic.co/t/multiple-logstash-config-files/130471 "2018-05-03T14:12:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamza\_Dhahri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_dhahri/32/29968_2.png) [@Hamza\_Dhahri](https://discuss.elastic.co/u/Hamza_Dhahri)\
**Post date:** [May 3, 2018, 2:12pm UTC](https://discuss.elastic.co/t/multiple-logstash-config-files/130471/1 "2018-05-03T14:12:53Z")

</div>

##### hello everyone

i have a log in which i have to parse some informations  
i have did 7 patterns (7 config files )  
and i have to stock this informations in elasticsearch  
well when i use logstash to run each config file  
it works !  
but when i use the directory path  
to run them all at the same time does not work!  
could ypu please help me

an example of a config file

input {  
file {  
path =\> ["C:/Users/THINKPAD/Downloads/logstash-6.2.2/essai/_._"]

}  
}

filter {  
grok {  
match =\> { "message"=\> "%{TIMESTAMP\_ISO8601:timestamp}%{GREEDYDATA:message1}\s+of\s%{NOTSPACE:nom\_job}%{GREEDYDATA:statut}\s+executed\sin\s%{GREEDYDATA:duration}"}  
}

if "\_grokparsefailure" in [tags] {  
drop {}  
}

}

output {  
elasticsearch { hosts =\> ["localhost:9200"]  
index=\>"conversion"}  
stdout {  
codec =\> rubydebug  
}  
}

---

<div class="post-metadata">

**Author:** ![Hamza\_Dhahri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_dhahri/32/29968_2.png) [@Hamza\_Dhahri](https://discuss.elastic.co/u/Hamza_Dhahri)\
**Post date:** [May 3, 2018, 2:16pm UTC](https://discuss.elastic.co/t/multiple-logstash-config-files/130471/2 "2018-05-03T14:16:21Z")

</div>

and i work for the same log !  
but when i didn't make

if "\_grokparsefailure" in [tags] {  
drop {}  
}

it works  
the problem is that when i didn't use it  
it parse all the lines (2000 lines )  
and in elasticsearch tables  
i found the researchable lines and the other lines  
some one can help me please !

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 3, 2018, 2:53pm UTC](https://discuss.elastic.co/t/multiple-logstash-config-files/130471/3 "2018-05-03T14:53:13Z")

</div>

Unless you use the multi-pipeline feature Logstash configuration files aren't independent. Logstash merges them together so that all events from all events will reach all filters and outputs unless you use conditionals.

This is an extremely common misconception that people ask about every week. Please consult old threads for elaborations.

---

<div class="post-metadata">

**Author:** ![Hamza\_Dhahri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_dhahri/32/29968_2.png) [@Hamza\_Dhahri](https://discuss.elastic.co/u/Hamza_Dhahri)\
**Post date:** [May 4, 2018, 9:27am UTC](https://discuss.elastic.co/t/multiple-logstash-config-files/130471/4 "2018-05-04T09:27:44Z")

</div>

i added a type for every config file and it works 100%  
thanks any way

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2018, 9:27am UTC](https://discuss.elastic.co/t/multiple-logstash-config-files/130471/5 "2018-06-01T09:27:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
